Fiche vulnérabilité
CVE-2022-26377 : faille élevée apache http server (CVSS 7.5)
Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 9 juin 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- apache http server
- fedoraproject fedora
- netapp clustered data ontap
Références
- Fiche CVE-2022-26377 sur le NVD (NIST)
- openwall.com/lists/oss-security/2022/06/08/2
- httpd.apache.org/security/vulnerabilities_24.html
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- security.gentoo.org/glsa/202208-20
- security.netapp.com/advisory/ntap-20220624-0005/